Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105699— Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers

Quick assessment

Affected
langflow-ai langflow
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Langflow 是一个用于构建和部署 AI 驱动智能体(agents)和工作流的工具。在版本 1.6.8 至 1.9.1 之间,Langflow 对项目中作用域的 MCP(Model Context Protocol)连接中的项目标识符进行了身份验证,但未对提供给 的资源 URI 实施授权控制。 函数将攻击者可控制的 URI 转发给 ,后者解析出 flow_id 和文件名,并调用 ,但在此过程中并未验证该 flow 是否属于已认证用户或当前项目。因此,任何有权访问项目中作用域 MCP 端点的用户,均可请求获取其他

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105699

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
Source: CVE Program / CVE List V5
Vulnerability Description
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to handle_read_resource, which parsed a flow_id and filename and called storage_service.get_file without verifying that the flow belonged to the authenticated user or current project. A user with access to any project-scoped MCP endpoint could therefore request another user's flow-backed file, while global handle_list_resources and handle_list_tools behavior could disclose flow and file identifiers that made targeting easier. The vulnerability disclosed uploaded documents, structured data, prompts, and other private flow artifacts across tenants but did not modify victim files or stored flows. This issue is fixed in version 1.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
langflow-ai langflow >= 1.6.8, <= 1.9.0 -

II. Public POCs for CVE-2026-105699

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105699

请登录查看更多情报信息。

Other References for CVE-2026-105699 (5)

Same Patch Batch · langflow-ai · 2026-10-05 · 5 CVEs total

CVE-2026-105697 9.9 CRITICAL Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati
CVE-2026-105740 9.9 CRITICAL Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O
CVE-2026-105741 7.1 HIGH Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
CVE-2026-105698 5.4 MEDIUM Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_i

IV. Related Vulnerabilities

V. Comments for CVE-2026-105699

No comments yet


Leave a comment